Description
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes when an administrator opens the "Merge with Another Site" dialog and the site selection list is displayed.Solution:

Update to Nx Witness VMS version 6.1.3 or later.
Published: 2026-08-24
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Administrator Account Takeover
Action: Patch promptly
AI Analysis

Impact

An unauthenticated attacker on the same local network can control another Nx server's site name field and inject JavaScript. When an authenticated administrator opens the "Merge with Another Site" dialog in the Web Administration interface, the malicious script executes in the administrator's browser, exfiltrating the session cookie. This permits takeover of the administrator account, effectively providing remote code execution within the browser context. The flaw is a stored cross‑site scripting vulnerability (CWE‑79).

Affected Systems

Network Optix Nx Witness VMS, versions prior to 6.1.3, on Linux, Windows, and macOS operating systems are vulnerable. The issue affects only the Web Administration interface accessed over HTTP/HTTPS and requires the administrator be logged in to use the web UI.

Risk and Exploitability

With a CVSS score of 8 the vulnerability is considered high severity. The EPSS metric is not available; it is not listed in CISA KEV, indicating no publicly reported exploits at the time of analysis. Exploitation requires an adjacent Nx server that an attacker can control and a logged‑in administrator who opens the merge dialog, so practical risk depends on network topology and user interaction. The high score and ability to steal session tokens make it a serious threat for organizations with lax network segmentation.

Generated by OpenCVE AI on August 24, 2026 at 19:47 UTC.

Remediation

Vendor Solution

Update to Nx Witness VMS version 6.1.3 or later.


OpenCVE Recommended Actions

  • Apply the vendor patch to Nx Witness VMS version 6.1.3 or newer.
  • Isolate the web administration servers from untrusted peers by enforcing network segmentation or firewall rules that prevent adjacent Nx servers from being reachable.
  • Restrict or monitor the "Merge with Another Site" dialog by implementing a web application firewall or browser security policy to block malicious script payloads.

Generated by OpenCVE AI on August 24, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Network Optix
Network Optix nx Witness Vms
Vendors & Products Network Optix
Network Optix nx Witness Vms

Mon, 24 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes when an administrator opens the "Merge with Another Site" dialog and the site selection list is displayed.Solution: Update to Nx Witness VMS version 6.1.3 or later.
Title Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltration via a rogue peer site name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Network Optix Nx Witness Vms
cve-icon MITRE

Status: PUBLISHED

Assigner: NX

Published:

Updated: 2026-08-24T20:21:30.345Z

Reserved: 2026-08-24T14:46:55.290Z

Link: CVE-2026-78414

cve-icon Vulnrichment

Updated: 2026-08-24T20:21:25.578Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T15:16:48.873

Modified: 2026-09-01T21:03:04.987

Link: CVE-2026-78414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')